Job Title: Application Security Tester / DevSecOps Lead
Berkeley Heights, NJ
Contract
Experience: 10+ Years
________________________________________
Role Overview
This is a hands-on DevSecOps Lead role responsible for owning and strengthening the security posture of the software delivery pipeline across three distinct technology stacks: modern cloud-native .NET Core / Azure AKS platform, legacy VB.NET / ASP.NET (.NET Framework 4.8) estate running on IIS, Core COBOL mainframe environment. The successful candidate will be responsible for configuring, tuning, and enforcing security controls within CI/CD pipelines, with direct accountability for transforming SCA, SAST, and DAST from advisory practices into mandatory, pipeline-blocking security gates across all three technology stacks. The role sits at the intersection of Application Security, DevOps Engineering, and Mainframe Modernization, requiring the ability to influence and collaborate effectively with developers across diverse environments from Kubernetes-based microservices and cloud-native applications to traditional COBOL batch workloads and CL-driven mainframe processes. The ideal candidate will combine deep technical expertise with hands-on execution, driving secure-by-design practices while ensuring security controls are seamlessly integrated into the software delivery lifecycle without compromising engineering velocity.
Key Responsibilities
Enforce Security Gates Across All Stacks
Extend and Mature Security Tooling Coverage
DevSecOps Pipeline Engineering
Establish Remediation SLAs
Governance, Metrics & Stakeholder Management
AI-Augmented Findings Orchestration & Remediation
Tools & Platforms
Category Tools
Source Control GitHub / GitLab
CI/CD GitHub Actions, Ansible, Harness
Artifact Management Nexus
SAST Fortify
SCA Sonatype
DAST WebInspect
Code Quality / Build Gating SonarQube, Build Breaker
Observability Dynatrace, Splunk
Essential Skills & Experience